A knowledge-based alert evaluation and security decision support framework

被引:0
|
作者
Yu, JQ [1 ]
Reddy, R [1 ]
Selliah, S [1 ]
Reddy, S [1 ]
机构
[1] Illinois Wesleyan Univ, Dept Math & Comp Sci, Bloomington, IL 61701 USA
关键词
IDS; vulnerability; alert management; security decision support; alert correlation;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper, a generic architecture for intrusion alert management, analysis and security decision support is described. The architecture is composed of four components: (1)Alert Aggregator, (2)Alert Evaluation and Security Decision Support Component, (3)Alert Correlator and (4)Synthetic Alert Report Generator. The core of this architecture is the Alert Evaluation and Security Decision Support component. The component provides a framework for knowledge-based alert evaluation and security decision support. The framework aims at reducing alert overload and false positive alerts, prioritizing alerts and providing real-time security decision support. This is accomplished by integrating knowledge of the protected network and host asset information and knowledge of known vulnerability requirements as well as specified security policies into the alert evaluation process. The alert evaluation and security decision support component as well as the alert aggregator have been implemented, and the implementation results are presented in this paper.
引用
收藏
页码:194 / 200
页数:7
相关论文
共 50 条
  • [41] A FRAMEWORK FOR DEVELOPING A KNOWLEDGE-BASED DECISION SUPPORT SYSTEM FOR MANAGEMENT OF VARIATION ORDERS FOR INSTITUTIONAL BUILDINGS
    Arain, Faisal Manzoor
    Pheng, Low Sui
    JOURNAL OF INFORMATION TECHNOLOGY IN CONSTRUCTION, 2006, 11 : 285 - 307
  • [42] Intelligent agents framework for developing knowledge-based decision support systems for collaborative organizational processes
    Bose, R
    EXPERT SYSTEMS WITH APPLICATIONS, 1996, 11 (03) : 247 - 261
  • [43] Integrated framework of knowledge-based decision support system for user-centered residential design
    Zhang, Yuxuan
    Chen, Yuan
    Li, Xinming
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 216
  • [44] A framework for developing a knowledge-based decision support system for management of variation orders for institutional buildings
    Arain, Faisal Manzoor
    Pheng, Low Sui
    Electronic Journal of Information Technology in Construction, 2006, 11 : 285 - 307
  • [45] Design and evaluation of a knowledge-based clinical decision support system for the psychiatric nursing process
    Ho, Kuei-Fang
    Chou, Po-Hsiang
    Chao, Jane C. -J.
    Hsu, Chien-Yeh
    Chung, Min-Huey
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2021, 207
  • [46] Construction and effectiveness evaluation of a knowledge-based infectious disease monitoring and decision support system
    Wang, Mengying
    Jia, Mo
    Wei, Zhenhao
    Wang, Wei
    Shang, Yafei
    Ji, Hong
    SCIENTIFIC REPORTS, 2023, 13 (01)
  • [47] Construction and effectiveness evaluation of a knowledge-based infectious disease monitoring and decision support system
    Mengying Wang
    Mo Jia
    Zhenhao Wei
    Wei Wang
    Yafei Shang
    Hong Ji
    Scientific Reports, 13
  • [48] TRINETR: An architecture for collaborative intrusion detection and knowledge-based alert evaluation
    Yu, JQ
    Reddy, YVR
    Selliah, S
    Reddy, S
    Bharadwaj, V
    Kankanahalli, S
    ADVANCED ENGINEERING INFORMATICS, 2005, 19 (02) : 93 - 101
  • [49] Knowledge-based reasoning and recommendation framework for intelligent decision making
    Ali, Rahman
    Afzal, Muhammad
    Sadiq, Muhammad
    Hussain, Maqbool
    Ali, Taqdir
    Lee, Sungyoung
    Khattak, Asad Masood
    EXPERT SYSTEMS, 2018, 35 (02)
  • [50] Effective model building in knowledge-based decision support system
    Han, SX
    Huang, TY
    PROCEEDINGS OF '96 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE & ENGINEERING, 1996, : 103 - 106